CVE-2025-52222
published 2026-04-08CVE-2025-52222: D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.33%
24.6th percentile
D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters in the radius_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | di-8003_firmware | — | — |
| dlink | di-8003g_firmware | — | — |
| dlink | di-8004w_firmware | — | — |
| dlink | di-8100_firmware | — | — |
| dlink | di-8100g_firmware | — | — |
| dlink | di-8200_firmware | — | — |
| dlink | di-8200g_firmware | — | — |
| dlink | di-8400_firmware | — | — |
| dlink | di-8500_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-08
Published